CVE-2026-92931: CWE-918: Server-Side Request Forgery in the Progress Sitefinity Next.js Renderer SDK
Published Oct 5, 2026
·Updated
CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.
Affected Software
1 affected component
npm/@progress/sitefinity-nextjs-sdk>=15.1.8326<=15.4.8637
Event History
Oct 5, 2026
CVE Published
via MITRE·01:06 PM
Data Sourced
via MITRE·01:06 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Deployments using the npm package @progress/sitefinity-nextjs-sdk at versions 15.1.8326 through 15.4.8637 are affected.
2
What does an attacker need to exploit this issue?
The issue may be exploited remotely without privileges or user interaction. Successful exploitation allows the attacker to cause server-side requests to an attacker-controlled host.
3
What is the potential impact of exploitation?
Server-side requests to an attacker-controlled host could expose sensitive information. The reported impact also includes high confidentiality, integrity, and availability effects.